<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T12:22:52.038841+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-33045</id>
    <title>CVE-2026-33045 — Home Assistant has stored XSS in history-graphs</title>
    <updated>2026-10-02T12:22:52.040575+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> home-assistant core</p>
<p>Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 2025.02 and prior to version 2026.01 the "remaining charge time"-sensor for mobile phones (imported/included from Android Auto it appears) is vulnerable cross-site scripting, similar to CVE-2025-62172. Version 2026.01 fixes the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-33045"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-46j8-vpx8-6p72</id>
    <title>GHSA-46j8-vpx8-6p72 — Home Assistant has stored XSS in history-graphs</title>
    <updated>2026-10-02T12:22:52.040627+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: homeassistant</p>
<p>### Summary
The "remaining charge time"-sensor for mobile phones (imported/included from Android Auto it appears) is vulnerable to the same issue as CVE-2025-62172.
&lt;img width="431" height="334" alt="image" src="https://github.com/user-attachments/assets/84e0dfad-b986-4e84-ad0e-674c5da88582" /&gt;
This also indicates that any sensor showing their name in the history-graph, is likely to be vulnerable to this issue.</p>
<p>### Details</p>
<p>Another entity was found which displays the same behavior as in this issue: [CVE-2025-62172](https://github.com/home-assistant/core/security/advisories/GHSA-mq77-rv97-285m)</p>
<p>The History-graph card will sometimes display the name of the entity it is displaying, when the graph is shown as a line with values on the x and y axis. This appears to be vulnerable to Cross-Site scripting (_XSS_) as it does not have any output escaping or sanitization.</p>
<p>The PoC in this instance only shows HTML-injection in the form of the `&lt;s&gt;` -tag being rendered as strike through, but the vulnerability also allows for injecting arbitrary tags which execute JavaScript, like the example given in the PoC description below.</p>
<p>### PoC
1. Register a new sensor (or device) or change the name of an existing one, which provides a location
2. Change the name to something malicious, for example `test &lt;img src=x onerror=alert(document.domain) /&gt;`
    For a new entity, it should work when setting the name. For old entities, go here:
&lt;img width="1300" height="411" alt="image" src="https://gi…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-46j8-vpx8-6p72"/>
  </entry>
</feed>
